Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile
Dmytro Oleksiuk 💥 [email protected]

@d_olex

zero-fucks-given infosec research | contacts: keybase.io/d_olex | 🇺🇦 Ukraine needs your help to kill Ruϟϟian zombies: savelife.in.ua/donate

ID: 244286442

linkhttp://blog.cr4.sh/ calendar_today28-01-2011 23:52:10

7,7K Tweet

12,12K Takipçi

1,1K Takip Edilen

Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile Photo

David Kaplan Also, conclusion is kind of weird: I used *correct* terminology introduced by platform vendor, binarly used they own *wrong* terminology to make loud PR claims and headlines, but... both parties are right?! I'm sorry, but there's a clear logical contradiction here

Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile Photo

@jckarter System Management Mode code also has its own protection rings 0 and 3 same as non-SMM code. I wonder how do we call CPL=0 mode of System Management Mode then, ring -2*2?

Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile Photo

Every single time > Found some cool vintage streamer or MO drive > Damn, it has external SCSI interface > Learning about all sort of cables and adapters > The ones I need costs x5 more than drive itself > Fuck this shit

Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile Photo

Periodic reminder: you don't have to buy skid's crap to get access to #UEFI firmware implant technology. You can download my FOSS & battle-tested UEFI boot backdoor for free, it has much more use-cases and deployment options than #BlackLotus github.com/Cr4sh/s6_pcie_…

Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile Photo

Psssst: someone, please tell Elmo that it’s possible to shutdown even more servers by removing all recommended & suggested tweets of random people from the feed, maybe it will work

Stephan van Schaik (@themadstephan) 's Twitter Profile Photo

Our survey of SGX attacks is out! Come learn about how SGX fails in real life. Check out our website sgx.fail including attacks on Secret Network and CyberLink PowerDVD.

Robert Graham (@erratarob) 's Twitter Profile Photo

By "AI ethics" people really mean a "censorship". AI's that reflect how people really thing are "dangerous", and instead, they try to construct AIs according how people should think instead.

Satoshi Tanda (@standa_t) 's Twitter Profile Photo

The UEFI Forum started to publish mapping of DBX entries and CVEs since last October. That helps IT pros and security software understand which threats are blocked or not significantly. Great improvement. uefi.org/revocationlist…

The UEFI Forum started to publish mapping of DBX entries and CVEs since last October. That helps IT pros and security software understand which threats are blocked or not significantly. Great improvement. 

uefi.org/revocationlist…
Yongdae Kim (yongdaek@infosec.exchange) (@yongdaek) 's Twitter Profile Photo

* LTESniffer: An Open-source LTE Downlink/Uplink Eavesdropper * We open-source LTESniffer, accepted at ACM WiSec '23. LTESniffer supports: Real-time decoding of + Downlink traffic from the base station. + Uplink traffic from nearby users. github.com/SysSec-KAIST/L…

Christian Werling (@_cwerling) 's Twitter Profile Photo

Disk encryption is critical in securing your data when you lose your device or an attacker gets physical access. But we found that if you don't use a BitLocker passphrase on an AMD system (before Windows even comes up), your data is not adequately secured: arxiv.org/abs/2304.14717

Gwaby (@pwissenlit) 's Twitter Profile Photo

Just published a blog post about the bug I found on EDK2. TL.DR. the bug is not outstanding, but the limited primitive it offers is a nice excuse to play with exploitation techniques in SMM. :) blog.quarkslab.com/for-science-us…

Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile Photo

Ha, didn't even know that I got CVE number for HP bugloader discovered few years ago. Original advisory doesn’t have any credits, I guess they didn't liked my typical twitter-disclosure lol: support.hpe.com/hpesc/public/d…

The Haag™ (@m_haggis) 's Twitter Profile Photo

We are excited to announce the launch of our latest project: Bootloaders.io. The inception of this project was sparked by the emergence of the BlackLotus bootkit. Bootloaders/kits - a subject I had never delved into before. My explorations into bootloaders and bootkits

Dmytro Oleksiuk 💥 d_olex@mastodon.social (@d_olex) 's Twitter Profile Photo

stacksmashing Pwnie Awards Ramtin Amin did exactly the same work and achieved exactly the same results in 2016-2017, many people been able to replicate this work. What’s the innovation here?